Malicious PDF — malware analysis report

Static analysis result for SHA-256 8b0a24c5435db504…

MALICIOUS

PDF

34.4 KB Created: 2021-07-03 17:24:42 +07:00 Authoring application: wkhtmltopdf 0.12.6 (via Qt 4.8.7)
MD5: 3d8dc1cc91b064156b4222daa68cd553 SHA-1: cdc33936d21df63eed2a0a70c6ddeb237c6ee9ec SHA-256: 8b0a24c5435db504c38ff2dcc23b876c2af1efa241523f85ad76012b99ea906a
102 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

This PDF document exhibits malicious behavior by acting as a link farm, directing users to numerous other PDFs hosted on external domains, likely as part of a scam or malware distribution scheme. The document body and extracted URLs suggest a lure related to free game items and cheats, aiming to trick users into clicking through to potentially harmful content. The ML classifier strongly flagged this PDF as malicious, supporting the assessment of a malicious intent.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9980

Heuristics 4

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Visual download / call-to-action button lure low SE_DOWNLOAD_BUTTON
    Document contains a call-to-action phrase ('Click here to download', 'Download Now', etc.) — low-signal unless other findings point to a malicious workflow
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://netcdn.tw/app/479516143/free-minecraft-games-for-kids-game-hack
    • http://library.acehresearch.org/repository/how-to-get-free-roebucks-in-roblox_GM431946152.pdf
    • http://library.acehresearch.org/repository/free-robux-openrewards_GM431946152.pdf
    • http://library.acehresearch.org/repository/can-you-play-minecraft-for-free_GM479516143.pdf
    • http://library.acehresearch.org/repository/coin-master-free-daily-spins-and-coins_GM406889139.pdf
    • http://library.acehresearch.org/repository/free-robux-2021_GM431946152.pdf
    • http://library.acehresearch.org/repository/how-to-get-minecraft-for-free-on-android_GM479516143.pdf
    • http://library.acehresearch.org/repository/how-to-get-robux-for-free-2021_GM431946152.pdf
    • http://library.acehresearch.org/repository/roblox-booga-booga-coin-hack_GM431946152.pdf
    • http://library.acehresearch.org/repository/is-minecraft-java-edition-free_GM479516143.pdf
    • http://library.acehresearch.org/repository/undetected-cheat-engine-for-roblox_GM431946152.pdf
    • http://library.acehresearch.org/repository/free-spins-coin-master-2021_GM406889139.pdf
    • http://library.acehresearch.org/repository/coin-master-hack-apk-ios_GM406889139.pdf
    • http://library.acehresearch.org/repository/roblox-in-cheat-ingine_GM431946152.pdf
    • http://library.acehresearch.org/repository/robux-fun-hack_GM431946152.pdf
    • http://library.acehresearch.org/repository/roblox-the-mad-murderer-chat-voice-free_GM431946152.pdf
    • http://library.acehresearch.org/repository/coin-master-heaven-free-spins-link_GM406889139.pdf
    • http://library.acehresearch.org/repository/minecraft-hacked-client-bedrock_GM479516143.pdf
    • http://library.acehresearch.org/repository/site-hack-roblox_GM431946152.pdf
    • http://library.acehresearch.org/repository/roblox-free-play-no-download_GM431946152.pdf
    • http://library.acehresearch.org/repository/free-robux-robot-verification_GM431946152.pdf
    • http://en.wikipedia.org/wiki/MIT_License

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000311b.bin
ced01493988f8f1cab163f42fff7f77cae02c0c6763066d0dc2aa62a05831e34
pdf-font-stream PDF embedded font (sfnt) at offset 0x311B 22568 bytes
font_01_sfnt_off00006345.bin
fce0cee9bb026e9b658c5a6be084441bf5d333caf380f9a351f6fa516673a190
pdf-font-stream PDF embedded font (sfnt) at offset 0x6345 18432 bytes